[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86239-en":3,"doc-seo-86239-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86239,1374391974585,"Genevieve","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Provable Remote Execution of Zero-Trust Authorization using SNARKs","Modernizing the security of operational technology systems for critical infrastructure is challenging due to constrained edge devices and the reliance on application gateways that enforce zero-trust authorization. Gateways must be deployed near distributed edges, kept patched, and managed with minimal downtime, making scaling and reliability difficult. PREZTA eliminates these gateways by executing policies inside a zero-knowledge virtual machine (zkVM) on the client and producing succinct SNARK proofs verifiable efficiently at the edge, enabling policy evolution without edge updates.","Prezta: Provable Remote Execution of Zero-Trust Authorization using SNARKs  \nZhongjing Wei*  \nUniversity of Illinois Urbana-Champaign [zwei26@illinois.edu](zwei26@illinois.edu)  \nYupeng Zhang  \nUniversity of Illinois Urbana-Champaign [zhangyp@illinois.edu](zhangyp@illinois.edu)  \nOsaid Muhammad Ameer* University of Illinois Urbana-Champaign [oameer2@illinois.edu](oameer2@illinois.edu)  \nNikita Borisov  \nUniversity of Illinois Urbana-Champaign [nikita@illinois.edu](nikita@illinois.edu)  \narXiv :2607 . 1 1466v 1 [ cs .CR] 13 Jul 2026  \nAbstract  \nModernizing the security of operational technology systems that control critical infrastructure has become a pressing challenge. Because edge devices have limited capabilities, modernization has relied on application gateways that interface with identity management systems and enforce access policies. These gateways are powerful enough to perform complex authorization decisions and support zero-trust architectures but create major deployment and management burdens: they must be collocated with remote, distributed edge devices, kept up to date with security patches, and managed with minimal downtime.  \nWe propose Provable Remote Execution of Zero-Trust Authorization (PREZTA), an architecture that eliminates these gateways by evaluating policies within a zero-knowledge virtual machine (zkVM) running on the client. The zkVM produces a succinct proof of authorization that edge devices can verify efficiently, extending the zero-trust security envelope to the edge. Policies and identity management schemes can evolve without updating edge devices.  \nTo demonstrate the feasibility of PREZTA, we implement a prototype, built using the RISC Zero zkVM, that supports XACML 3.0 policies and JWT identity claims. While zkVMs introduce substantial proof overhead, we mitigate this by compiling policies to Rust code and pre-compiling regular expressions. Combined with optimized signature verification and JWT parsing, these measures reduce prover time by more than an order of magnitude. Our compiler correctly implements 83% ofthe XACML 3.0 conformance suite, with proof generation completing in tens of seconds on a desktop. Verification, by contrast, takes only tens of milliseconds—fast enough for even resource-constrained edge devices.  \n1 Introduction  \nOperational technology (OT) networks [49] provide a networked interface to physical devices, such as those used in  \n* * The authors contribute equally to this paper.  \nmanufacturing, energy systems, and various forms of infrastructure, from water treatment to traffic control. Devices in these networks typically have rudimentary built-in security protections, owing to their limited computational capabilities and upgrade cycles that can range to several decades [43] . Yet the security of many of these systems is paramount due to the critical importance of the systems and infrastructure that they monitor and control [32, 34] . This has led to efforts to extend modern security practices and, in particular, zero-trust architectures [45], to OT networks [30, 36, 42] .  \nA key tool in this effort has been the use of application gateways. These gateways implement modern security practices, such as the use of sophisticated role-and attribute-based policies [28, 47], and interfacing with identity management systems that can implement two-factor authentication. These gateways, however, become a critical component, and their failures or compromise can result in a loss of availability or a security breach, respectively. The network linking the gateways to OT devices is implicitly trusted, so in distributed infrastructure, many gateways are needed to collocate them with the OT devices. This creates a significant management problem, where gateways must be kept secured, patched against vulnerabilities, and available.  \nOur Contributions. To mitigate this management problem, we propose an alternate architecture, Provable Remote Execution of Zero-Trust Authorization, or PR","cbCaiozkGcKIBUpc","https://ap.wps.com/l/cbCaiozkGcKIBUpc","pdf",331787,2,1,20,"English","en",105,"# Abstract\n# Introduction\n## Motivation from OT Networks\n## Application Gateways and Their Burdens\n## Our Contributions: PREZTA","[{\"question\":\"What problem does PREZTA address in OT zero-trust deployments?\",\"answer\":\"PREZTA addresses the management and deployment burden of application gateways that must be collocated with distributed edge devices, kept patched, and kept highly available for authorization decisions.\"},{\"question\":\"How does PREZTA replace application gateways?\",\"answer\":\"PREZTA executes zero-trust authorization policies inside a zkVM on the client and generates a succinct SNARK proof that edge devices can verify efficiently.\"},{\"question\":\"What does the prototype support, and how is performance improved?\",\"answer\":\"The prototype supports XACML 3.0 policies and JWT identity claims. It mitigates zkVM proof overhead by compiling policies to Rust code, pre-compiling regular expressions, and optimizing signature verification and JWT parsing to reduce prover time by more than an order of magnitude.\"}]",1784209719,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"provable-remote-execution-of-zero-trust-authorization-using-snarks","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/provable-remote-execution-of-zero-trust-authorization-using-snarks/86239/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does PREZTA address in OT zero-trust deployments?","Question",{"text":75,"@type":76},"PREZTA addresses the management and deployment burden of application gateways that must be collocated with distributed edge devices, kept patched, and kept highly available for authorization decisions.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does PREZTA replace application gateways?",{"text":80,"@type":76},"PREZTA executes zero-trust authorization policies inside a zkVM on the client and generates a succinct SNARK proof that edge devices can verify efficiently.",{"name":82,"@type":73,"acceptedAnswer":83},"What does the prototype support, and how is performance improved?",{"text":84,"@type":76},"The prototype supports XACML 3.0 policies and JWT identity claims. It mitigates zkVM proof overhead by compiling policies to Rust code, pre-compiling regular expressions, and optimizing signature verification and JWT parsing to reduce prover time by more than an order of magnitude.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":29,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":22,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":22,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]